View Single Post
Old 07-03-2007, 06:43 PM   #3 (permalink)
tstevens
Registered User
 
Join Date: Jul 2007
Posts: 7
OS: WinXP


Re: Ad popups/spyware/who knows what :(

Nuthin' like self-help :)

So after reviewing my log file, and focusing on those suspicious DLLs, I narrowed this down to the so-called "Vundo" aka "Virtumonde" virus.

I found this tool, "vundofix".

http://www.atribune.org/content/view/24/2/

I ran it & it id'd a good 10-15 files flagged as part of this virus - clicked remove vundo, it deleted them, couldn't delete 2 of them (the 2 suspicious dll's, C:\WINDOWS\system32\awvtr.dll & C:\WINDOWS\system32\ljjjhgh.dll that led me to that tool in the first place).

It then prompts to reboot, vundofix pops up after reboot & you click remove vundo again & this time those files are deleted, and AFAICT, this freakin thing is gone. Thank goodness...

Re-running the panda activescan thing right now, so far it has found fewer spyware items than before (211 instead of ~230) and has not id'd any viruses yet, so, x'ing fingers...

Anyway, just posting this info here so maybe others can find it & find the solution in future. What a hassle, a pox on whoever writes this #$*(&#$ stuff



Cheers,
Tim

Last edited by tstevens; 07-03-2007 at 06:45 PM.
tstevens is offline